Answer:
Security controls are measures taken to protect information and systems from threats. They are derived from policies. Security controls can be classified into three types: administrative (policies, procedures, guidelines for the business and personnel), technical (firewalls, surveillance systems, antivirus software), and physical (tangible measures to prevent unauthorized access to systems or assets). These controls are derived from an organization's risk management process and are designed to reduce or mitigate the risk to the organization's assets.
Therefore, the correct answer is:
1. Security controls are measures taken to protect information and systems from threats. They are derived from policies.
Explanation: